[codex] docs: add OpenCoven IP protection records#5
Merged
Conversation
BunsDev
force-pushed
the
codex/ip-protection-record-20260704
branch
from
July 4, 2026 14:21
ed1a9dd to
b6e9b1a
Compare
BunsDev
marked this pull request as ready for review
July 4, 2026 14:52
There was a problem hiding this comment.
Pull request overview
Adds top-level governance/legal documentation intended to establish IP protection terms, provenance, contribution requirements, and a security disclosure process for the OpenCoven project.
Changes:
- Adds a
PATENTSnon-assertion pledge and prior-art notice. - Adds
PROVENANCE.mddescribing OpenCoven’s origin and architectural concept timeline. - Adds
CONTRIBUTING.md(DCO + patent non-assertion terms) andSECURITY.md(vulnerability reporting policy).
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 6 comments.
| File | Description |
|---|---|
| SECURITY.md | Introduces a security policy and vulnerability reporting instructions. |
| PROVENANCE.md | Adds a provenance/origin record for OpenCoven concepts and publication timeline. |
| PATENTS | Adds a patent non-assertion pledge and prior-art notice. |
| CONTRIBUTING.md | Adds contribution terms including DCO sign-off instructions and patent non-assertion language. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+24
to
+27
| ### 1. The Familiar Identity Model | ||
| **First appeared:** `coven-cli/src/familiar_identity.rs`, commit history from 2026-04-27 | ||
|
|
||
| A named, role-scoped agent persona — a "familiar" — resolved from a configuration manifest (`familiars.toml`) and attached to a session via a CLI flag or runtime config. Each familiar has an `id`, `display_name`, and `role`. The familiar model is the foundational identity primitive for multi-agent systems in OpenCoven. |
Comment on lines
+31
to
+34
| ### 2. The Agent Spawn Harness | ||
| **First appeared:** `pty_runner.rs:307` (`spawn_piped_with_observer`), commit history from 2026-04-27 | ||
|
|
||
| A structured dispatch pattern for launching configured agent/harness processes. The pattern validates a harness allowlist, canonicalizes working directory, checks session state, then dispatches to one of a defined set of low-level spawn primitives. This is the root pattern from which single-chokepoint process execution architectures in agent systems derive. |
Comment on lines
+7
to
+13
| If you discover a security vulnerability in OpenCoven, please report it responsibly. | ||
|
|
||
| **Do not open a public GitHub issue for security vulnerabilities.** | ||
|
|
||
| Contact the maintainers directly: | ||
| - Discord: https://discord.gg/OpenCoven (DM @BunsDev) | ||
| - Or open a GitHub Security Advisory on the repository |
Comment on lines
+1
to
+3
| # Contributing to OpenCoven | ||
|
|
||
| Thank you for your interest in contributing. OpenCoven is MIT licensed and community-driven. We want contributing to be easy, open, and safe for everyone. |
Comment on lines
+5
to
+10
| OpenCoven is MIT licensed. The maintainers of this project have not filed and do not intend to file patents on the architectural patterns, protocols, or mechanisms described in this repository. | ||
|
|
||
| **Architectural concepts originating in this repository include, but are not limited to:** | ||
|
|
||
| - The familiar identity model: a named, role-scoped agent persona resolved from a configuration manifest and attached to a session | ||
| - The agent spawn harness: a structured dispatch pattern that validates and routes process execution through a defined set of primitives |
Comment on lines
+11
to
+13
| - The multi-agent orchestration substrate: composable, purpose-scoped agents ("familiars") coordinating through structured routing with shared session context | ||
| - The session memory and continuity substrate (OpenTrust): durable, portable agent memory and session state with provenance tracking | ||
| - The graded approval tier model: auto → familiar-review → human-review → human-required escalation for agent actions affecting protected resources |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds the OpenCoven root IP protection and disclosure documents:
PATENTS: patent non-assertion pledge and prior-art noticePROVENANCE.md: origin and publication recordCONTRIBUTING.md: DCO and patent contribution terms, merged with any existing repo guidanceSECURITY.md: responsible disclosure policy, merged with any existing repo guidanceValidation
PATENTS,PROVENANCE.md,CONTRIBUTING.md,SECURITY.mdgit diff --checkpassed locally